Help
Privacy notice
Draft wording (version 2026-10-v2), still to be confirmed by the steering group.
Who we are: P.O.R.C.H., a voluntary residents' group in the Coton Hill area of Shrewsbury. Data lead: [DATA LEAD]. Contact: [CONTACT EMAIL]. [USER TO CONFIRM: name the data lead.]
ICO fee: [USER TO CONFIRM: complete the ICO's online data protection fee self-assessment and record the result here. Many not-for-profit groups are exempt, but the group must check.]
What we hold, and why:
- Members' email addresses and roles, so you can log in. Lawful basis: legitimate interests in running the group's private workspace.
- Community reports you choose to submit. Lawful basis: your explicit consent. Reports may touch on alleged offences (criminal-offence data) or health. To keep this to a minimum:
- we ask you not to identify anyone
- we remove anything identifying, including details about other people, before other members can see a report
- only anonymous aggregate figures are shared outside the group
- Public documents: council papers, planning documents, news reports, FOI responses and public web pages such as FixMyStreet. Councillors and officials appear in their public roles. Some of these documents also name private individuals, for example people quoted in the press or people who commented on a planning application. Lawful basis: legitimate interests in understanding and following the Coton Hill House scheme. [USER TO CONFIRM: keep a short written Legitimate Interests Assessment.]
Personal data from public sources: where a document is already public, we show it as it was published, with a "Publicly available" label saying where and when we checked it. We don't add to what was published, and we don't speculate about anyone's identity. We never identify, or guess at the identity of, residents of Coton Hill House. If you are named in a document on this site, you can ask us to remove or hide your name at [CONTACT EMAIL]. We will do so unless there is a good reason to keep it, and we aim to reply within [one month]. [USER TO CONFIRM]
Where it is stored, and who processes it for us:
- Cloudflare hosts the site, the database and the file storage, and runs the login. The database and file storage are set to EU jurisdiction.
- Google [USER TO CONFIRM: what Google provides, e.g. the group's email account used for site contact or sign-in].
- Some processing by these providers may take place outside the UK. Where it does, they rely on UK-approved safeguards, for example adequacy regulations or standard contractual clauses. [USER TO CONFIRM]
Who sees it:
- Access needs a login with an approved email address.
- Two named admins see community reports before redaction. Members see them only after a second admin has approved the redaction, and only if the reporter allowed it.
- Private correspondence is seen by admins only.
- We do not sell personal data. We do not publish community reports or private correspondence.
If the research is opened to the public: after peer review, the group may open its public research (findings, timeline, sources) to everyone. If so, we will update this notice first and check every public document again for names that are not needed. Community reports, group action plans and private correspondence will stay login-only. [USER TO CONFIRM]
How long:
- Community reports: original words deleted once redacted (30 days at most); redacted reports kept for [24 months], then deleted automatically.
- Member accounts: removed 30 days after a member leaves.
- Audit logs: [12 months]. [USER TO CONFIRM]
Your rights: you can ask to see, correct or delete your data, or withdraw consent, at [CONTACT EMAIL]. Where we rely on legitimate interests (including for public documents that name you), you have the right to object. If you do, we will stop unless we have compelling reasons to continue. You can also complain to the Information Commissioner's Office (ico.org.uk).